Nubea Privacy Policy
1. Introduction
Version 3.0 - Effective March 8, 2026
This Privacy Policy applies to the use of the website published at the URL https://nubea.com.ar and to the Nubea application available in the application stores of e-commerce platforms (including Shopify and Tiendanube), whose main function is to provide automation and digital marketing services for online stores, including pop-ups, stock notifications, WhatsApp automations and more.
By installing our application, accessing our website or using our Services, you agree to be bound by this Privacy Policy and our Terms and Conditions.
This policy describes what personal data we collect, how we use it, who we share it with, how we protect it, and what rights you have as the owner of that data. Nubea is committed to protecting the privacy of merchants and end customers of its stores.
2. Information we collect
2.1. Merchant details
By registering or installing the Nubea application, we collect the following data from the merchant:
- Full name and store name
- Phone
- Store domain
- Subscription plan and billing information
2.2. Customer data obtained through platform APIs
Through the APIs of the electronic commerce platform (Shopify, Tiendanube), we access the following end customer data exclusively to provide the functionality of the application:
- Customer data: name, email, phone
- Order data: purchase history, abandoned carts, payment statuses
- Product data: information on products viewed or purchased
- Shipping details: fulfillment information linked to orders
Data Minimization: We only access and process the minimum data necessary to provide the functionality of the application to the merchant. We do not request access to data that is not strictly required for the operation of our services.
2.3. Navigation data
For users browsing third-party sites that use our widgets:
- Date and time of visit
- URL of the visited page
- Title and content of the page
- Product data displayed
- Browser language
2.4. Notification data
We collect anonymous information about the performance of notifications sent:
- Viewing date
- Sale date
2.5. Cookies and similar technologies
We use cookies, tags and other technologies to improve your experience and analyze the use of our services. For more information, see section 12 (Cookie Policy).
2.6. IP address and identifiers
We may collect your IP address and browser identifiers to:
- Improve service quality
- Diagnose connection problems
- Identify your account when you sign in
- Prevent fraud and abuse
3. How we use your information
We use your personal information for the following specific and limited purposes:
- Account management: allow you to access your information and provide you with personalized content
- Automations: configure and run WhatsApp automations (abandoned carts, pending payments, fulfilled orders), stock notifications and other services
- Newsletter and pop-ups: manage the capture of subscribers and the sending of marketing communications on behalf of the merchant
- Analysis and statistics: provide performance metrics of automations and conversions to the merchant
- Service improvement: develop and manage our websites, services and customer support
- Communication: send you newsletters, updates and notifications about our services
Purpose limitation: We do not process personal data for purposes other than those stated here. We do not sell, rent or use end customer data for our own advertising, independent profiling or any purpose other than providing service to the merchant.
4. How we share your information
Nubea will not sell, rent or share your personal information with third parties without your prior consent, except in the following circumstances:
4.1. Service providers
We share information with providers who help us provide our services, including:
- Amazon Web Services (AWS): infrastructure hosting and email delivery (SES)
- MercadoPago: subscription payment processing
- PostHog: product analysis (anonymized data)
All of our suppliers are contractually obliged to protect your information with the same level of security and not to use the data for their own purposes.
4.2. Legal compliance
We may disclose information if required to do so by applicable law, rule or regulation, or in response to a court order or valid government request.
4.3. Safety and security
We may share information to protect the rights, property or safety of Nubea, our users or third parties.
5. Information security
Nubea implements appropriate technical and organizational measures to protect your personal data, including:
5.1. Encryption
- Encryption in transit: All communications between your browser and our servers are over HTTPS/TLS.
- Encryption at rest: Data stored in our databases is encrypted
- Encrypted backups: Data backups are protected with encryption
5.2. Access control
- Limited access: Nubea operates with a small team. Direct access to personal data of merchants' customers is restricted exclusively to authorized technical personnel who need it for the operation and maintenance of the service. Currently, given the size of the operation, routine employee access to customer personal data is not required.
- Secure authentication: We require strong passwords and strong authentication for all accounts with access to internal systems
- Access log: We maintain access logs to protected customer data that are reviewed periodically
5.3. Storage and data loss prevention
- Separation of environments: test and production data are kept completely separate
- Data loss prevention strategy: We have a documented data loss prevention (DLP) strategy that includes regular automated backups, data replication across multiple availability zones, data integrity monitoring, and disaster recovery procedures.
- Retention periods: We ensure that personal data is not retained longer than necessary for the stated purposes, with automatic deletion policies upon expiration of the retention period
5.4. Incident response
- Incident response policy: We have a documented security incident response plan that includes severity scales, roles, escalation, and required actions. In the event of a security breach affecting personal data, we will notify affected merchants and competent authorities without undue delay
However, we cannot guarantee the absolute security of information transmitted over the Internet. We recommend that you keep your access credentials secure and not share them with third parties.
6. Your rights
Nubea provides the same privacy rights for all personal data, regardless of the individual's location. As the owner of personal data, you have the following rights:
6.1. Access and rectification
You have the right to access, rectify and update your personal data if it is inaccurate or incomplete.
6.2. Elimination
You can request deletion of your personal data at any time. We will process your request within 30 days of receipt, unless there is a legal obligation that requires us to retain certain information.
6.3. Revocation of consent and opt-out
You have the right to revoke your consent to the processing of your personal data at any time. We respect and enforce customer consent decisions, including opt-out decisions from the sale of their data. Nubea does not sell personal data, but in any case we respect and apply the opt-out preferences of each user.
6.4. Portability
You can request that your personal data be transferred to another service provider in a structured and commonly used format.
6.5. Processing restriction
You can request that we limit the processing of your personal data in certain circumstances.
6.6. Automated decisions
If we use algorithms or automated processes to make decisions that have legal or significant effects on you, you have the right to request the exclusion of such automated processing.
To exercise any of these rights, please contact us at: ayuda@nubea.com.ar
7. Data requests and deletion
Nubea complies with data and deletion requests required by e-commerce platforms and applicable privacy laws:
- Customer data request: When a customer requests access to the data we store about them, we process the request and provide the information within 30 days
- Deletion of customer data: When a customer or merchant requests the deletion of personal data, we proceed to delete or anonymize the information within 30 days, unless legally required to retain it.
- Uninstalling the app: When a merchant uninstalls our app, we delete data associated with their store within 30 days of uninstallation, except for data we are required to retain due to legal or contractual obligations.
8. Data retention
We retain personal data only for as long as necessary to fulfill the purposes for which it was collected. The specific retention periods are:
- Merchant account details: while the account is active and up to 30 days after uninstalling the app
- End customer data: as long as the merchant has an active account and needs them for the functionality of the service
- Automation execution data: up to 12 months from execution, for reports and analysis
- Newsletter subscriber data: as long as the merchant has an active account or until the subscriber requests its deletion
- Security and access logs: up to 12 months
- Billing information: as required by applicable tax laws (generally up to 10 years)
Once the retention period has expired, the data will be securely deleted or anonymized.
9. International transfers
Nubea is based in Argentina. Personal data may be transferred to and stored on servers located at:
- USA: infrastructure services (AWS) and processing
- European Union: depending on the service providers used
In the event of transfers to countries with different levels of data protection, we implement appropriate contractual safeguards and security measures to ensure the protection of your data, including standard contractual clauses where applicable.
10. Compliance with privacy laws
Nubea takes a standardized approach to privacy, providing the same rights to all users regardless of their geographic location:
- Personal Data Protection Law (Argentina): We comply with Law 25,326 and its complementary provisions
- GDPR (European Union): We respect the rights of access, rectification, elimination, restriction, portability and opposition to processing
- CCPA/CPRA (California): California residents have the right to know what data we collect, request its deletion, and opt out of data sales (Nubea does not sell personal data)
- US State Privacy Laws: We comply with applicable privacy laws of the US states.
11. Data protection compliance for Shopify
As an application published in the Shopify ecosystem, Nubea complies with the data protection and privacy requirements established by the platform. Below we detail our compliance in each required area:
11.1. Purpose and data minimization
- We process the minimum amount of personal data necessary to deliver value to merchants
- We communicate to merchants what personal data we process and for what purposes through this policy and during the installation process
- We strictly limit the use of personal data to the stated purpose
11.2. Consent and data protection agreements
- We maintain data protection and privacy agreements with our merchants, established through these Terms and Conditions and this Privacy Policy, which constitute a binding data processing agreement (DPA).
- We respect and apply the consent decisions of end customers
- We respect and implement customers' decisions to opt-out of the sale of their data.
- Where personal data is used for automated decision-making that may have legal or significant effects, customers may request opt-out of such processing.
11.3. Storage and retention
- We maintain defined retention periods which ensure that personal data is not kept longer than necessary (see section 8)
11.4. Data security
- We use encryption for data in transit (HTTPS/TLS) and at rest (database encryption)
- We use encryption for data backups
- We completely separate test data and production data
- We have a documented data loss prevention (DLP) strategy
11.5. Access and control
- Access to personal customer data is restricted to authorized technical personnel. Given the current size of the operation, additional employee routine access to personal customer data is not required.
- We enforce strong password requirements for all accounts with access to internal systems
- We log access to personal data and review the logs periodically
- We have a documented security incident response policy
12. Cookies Policy
We use cookies to improve your experience on our website and analyze the use of our services.
12.1. What are cookies?
Cookies are small text files that are stored on your device when you visit our website. They help us remember your preferences and improve your experience.
12.2. Types of cookies we use
- Essential cookies: necessary for the basic operation of the site
- Performance cookies: help us understand how the site is used
- Functionality cookies: remember your preferences and settings
- Marketing cookies: used to display relevant advertising
12.3. Cookie control
You can control which cookies you accept by configuring your browser. Please note that disabling certain cookies may affect the functionality of our site.
13. Links to external sites
Our site may contain links to other websites which are not under our control. We are not responsible for the privacy practices or the content of such sites. We recommend that you review the privacy policies of those sites.
14. Modifications to this policy
Nubea may modify this Privacy Policy at any time. Modifications will be posted on our website and you will be notified of significant changes by email.
Your continued use of our services after the publication of the new version will imply acceptance of the changes.
15. Contact
If you have questions or concerns about this Privacy Policy, or wish to exercise your rights, please contact us:
Nubea
ayuda@nubea.com.ar
We will respond to your inquiry within 2 business days
16. Acceptance of terms
Access and use of our website, installation of the application, and provision of personal data implies full acceptance of this Privacy Policy.
If you do not agree with the terms of this policy, please refrain from using our services or providing any personal data.
Effective date: This policy became effective on March 8, 2026 and remains in effect until modified or replaced. Replaces version 2.0 dated March 3, 2026.
